Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / 
security-tracker


Commits:
58a26869 by security tracker role at 2026-08-16T19:14:21+00:00
automatic update

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -1,14 +1,62 @@
-CVE-2026-72888
+CVE-2026-74797 (OpenTofu versions before 1.11.4 contain a denial of service 
vulnerabil ...)
+       TODO: check
+CVE-2026-74796 (OpenTofu before 1.11.7 fails to validate existing symlinks in 
the prov ...)
+       TODO: check
+CVE-2026-74795 (Scriban before 6.6.0 contains an uncontrolled recursion 
vulnerability  ...)
+       TODO: check
+CVE-2026-74794 (Scriban before 6.6.0 contains an infinite recursion 
vulnerability in o ...)
+       TODO: check
+CVE-2026-74792 (Scriban before 7.0.0 (affected versions <= 6.6.0) contains a 
stack ove ...)
+       TODO: check
+CVE-2026-74791 (Scriban before 7.0.0 fails to clear the CachedTemplates 
dictionary whe ...)
+       TODO: check
+CVE-2026-74790 (Scriban before 7.0.0 caches TypedObjectAccessor by Type only 
without c ...)
+       TODO: check
+CVE-2026-74789 (Scriban before 7.0.0 (affected <= 6.6.0) applies its LoopLimit 
constra ...)
+       TODO: check
+CVE-2026-74788 (Scriban before 7.0.0 (affected versions <= 6.6.0) contains an 
uncontro ...)
+       TODO: check
+CVE-2026-74787 (Scriban before 7.0.0 contains an uncontrolled recursion 
vulnerability  ...)
+       TODO: check
+CVE-2026-74786 (Scriban before 7.0.0 (affected versions <= 6.6.0) contains a 
denial-of ...)
+       TODO: check
+CVE-2026-74785 (Scriban before 7.0.0 contains three distinct denial-of-service 
vulnera ...)
+       TODO: check
+CVE-2026-74784 (Scriban before 7.2.0 contains a denial of service 
vulnerability in the ...)
+       TODO: check
+CVE-2026-74783 (Scriban versions 6.6.0 through 7.2.0 contain a non-enforcing 
Expressio ...)
+       TODO: check
+CVE-2026-74251 (Joomla Extension - phoca.cz -  Unauthenticated SQL injection 
via attri ...)
+       TODO: check
+CVE-2026-73062 (Scriban versions 3.0.0 through 7.2.0 contain a denial of 
service vulne ...)
+       TODO: check
+CVE-2026-73061 (Scriban before 7.2.2 contains an access-modifier bypass 
vulnerability  ...)
+       TODO: check
+CVE-2026-73060 (Scriban versions from 3.0.0 through 7.2.5 contain a denial of 
service  ...)
+       TODO: check
+CVE-2026-73059 (stoatchat before 0.15.0 contains a permission bypass 
vulnerability in  ...)
+       TODO: check
+CVE-2026-73058 (stoatchat versions before 0.15.0 fail to block the IPv6 
unspecified ad ...)
+       TODO: check
+CVE-2026-73057 (stoatchat before 0.15.0 fails to validate SVG viewBox 
dimensions in th ...)
+       TODO: check
+CVE-2026-73056 (SiYuan kernel versions before 3.7.4 contain an improper 
restriction of ...)
+       TODO: check
+CVE-2024-58375 (OpenTofu versions 1.8.0 through 1.8.2 do not properly restrict 
sensiti ...)
+       TODO: check
+CVE-2024-13784 (The Contact Form, Survey, Quiz & Popup Form Builder \u2013 
ARForms plu ...)
+       TODO: check
+CVE-2026-72888 (Net::OAuth versions before 0.32 for Perl allow memory 
exhaustion via u ...)
        - libnet-oauth-perl 0.32-1 (bug #1144539)
        NOTE: https://lists.security.metacpan.org/cve-announce/msg/42733455/
        NOTE: 
https://github.com/vurtdev/Net-OAuth/security/advisories/GHSA-m2cv-cq5x-47ph
        NOTE: Fixed by: 
https://github.com/vurtdev/Net-OAuth/commit/ee713fc96263c70b3b9a5280612618b474576f8f
-CVE-2026-72887
+CVE-2026-72887 (Net::OAuth::Client versions before 0.32 for Perl allow the 
service pro ...)
        - libnet-oauth-perl 0.32-1 (bug #1144539)
        NOTE: https://lists.security.metacpan.org/cve-announce/msg/42733454/
        NOTE: 
https://github.com/vurtdev/Net-OAuth/security/advisories/GHSA-jh72-4qq2-8j6g
        NOTE: Fixed by: 
https://github.com/vurtdev/Net-OAuth/commit/fd505dac1988723ed96721657663f2e4ac731644
-CVE-2026-74578 [crypto: algif_skcipher - force synchronous processing on trees 
without ctx->state]
+CVE-2026-74578 (In the Linux kernel, the following vulnerability has been 
resolved:  c ...)
        - linux 7.1.5-1
        [trixie] - linux 6.12.100-1
        [bookworm] - linux 6.1.180-1
@@ -10378,7 +10426,7 @@ CVE-2025-13294 (An unauthenticated SQL injection 
vulnerability exists in the web
        NOT-FOR-US: TBEA TLogger
 CVE-2025-13293 (A hard-coded or default root account credential in TBEA 
TLogger V2.1.0 ...)
        NOT-FOR-US: TBEA TLogger
-CVE-2026-19349
+CVE-2026-19349 (Lemonldap::NG::Portal versions from 2.0.0 before 2.16.9, from 
2.17.0 b ...)
        {DSA-6434-1 DLA-4734-1}
        - lemonldap-ng 2.23.3+ds-1
        NOTE: 
https://gitlab.ow2.org/lemonldap-ng/lemonldap-ng/-/commit/8c6015d6f0b4f1aa78bd54e159a74cd151e8e00d
 (v2.23.3)
@@ -14429,16 +14477,17 @@ CVE-2026-43622 (llama.cpp builds b1886 through b7445 
contain a double free vulne
 CVE-2026-3430 (The Creative Mail WordPress plugin from 1.6.5 to 1.6.9 does not 
saniti ...)
        NOT-FOR-US: WordPress plugin
 CVE-2026-34502 (Heap-based Buffer Overflow vulnerability in Apache Portable 
Runtime Ut ...)
-       {DSA-6437-1}
+       {DSA-6437-1 DLA-4742-1}
        - apr-util 1.6.4-1 (bug #1143837)
        NOTE: https://lists.apache.org/thread/spk5643m4vq0mb8h5b9hz9gkp57ombl8
        NOTE: Fixed by: 
https://github.com/apache/apr-util/commit/f1c98dd0847c43375daf3789c936685adbc6d872
 (1.6.4-rc1-candidate)
 CVE-2026-34501 (Heap-based Buffer Overflow vulnerability in Apache Portable 
Runtime Ut ...)
-       {DSA-6437-1}
+       {DSA-6437-1 DLA-4742-1}
        - apr-util 1.6.4-1 (bug #1143837)
        NOTE: https://lists.apache.org/thread/o8h6c7cq86fplxlnry6c3rn9x0ovq8mv
        NOTE: Fixed by: 
https://github.com/apache/apr-util/commit/e8f36bd5f1cc1c82bed1ae52d5699a4c610251c2
 (1.6.4-rc1-candidate)
 CVE-2026-34191 (Improper Neutralization of Special Elements used in an SQL 
Command ('S ...)
+       {DLA-4742-1}
        - apr-util 1.6.4-1 (bug #1143837; unimportant)
        [trixie] - apr-util 1.6.3-3+deb13u1
        NOTE: https://lists.apache.org/thread/8xch90zogywwpo5wnsf4o088mkxy4qtf
@@ -14449,7 +14498,7 @@ CVE-2026-32548 (Unauthenticated Broken Access Control 
in SureCart <= 4.6.2 versi
 CVE-2026-32469 (Unauthenticated Bypass Vulnerability in CAPTCHA 4WP <= 7.6.0 
versions.)
        NOT-FOR-US: WordPress plugin or theme
 CVE-2026-32327 (A bug in APR-util version 1.6.3 (and earlier) allows a stack 
recursion ...)
-       {DSA-6437-1}
+       {DSA-6437-1 DLA-4742-1}
        - apr-util 1.6.4-1 (bug #1143837)
        NOTE: https://lists.apache.org/thread/hq27vj8yfno9tkwv0fpj6jksfzgxvth1
        NOTE: Fixed by: 
https://github.com/apache/apr-util/commit/414e12e427c89f135d8ee66ab1203feffd3e2bd8
 (1.6.4-rc1-candidate)
@@ -14573,7 +14622,7 @@ CVE-2026-0637 (When an Event Publisher output adapter 
is configured with irrelev
 CVE-2025-9266 (The Accelerate theme for WordPress is vulnerable to 
unauthorized modif ...)
        NOT-FOR-US: WordPress plugin
 CVE-2025-49506 (APR-util versions 1.6.3 (and earlier) function 
apr_password_validate() ...)
-       {DSA-6437-1}
+       {DSA-6437-1 DLA-4742-1}
        - apr-util 1.6.4-1 (bug #1143837)
        NOTE: https://lists.apache.org/thread/2v8o3bj9pb7lfcr57bdnjg9xfkj04mg5
        NOTE: Fixed by: 
https://github.com/apache/apr-util/commit/f77a20761cb15686f8d4de5b5eafc534ae24b19e
 (1.6.4-rc1-candidate)
@@ -18191,7 +18240,7 @@ CVE-2026-62313 [Project isolation restriction bypass by 
omitting security.idmap.
        NOTE: 
https://github.com/lxc/incus/security/advisories/GHSA-53cg-qvg7-m8vg
        NOTE: https://github.com/lxc/incus/pull/3750
 CVE-2026-55707 (In OpenStack Neutron before 28.0.2, the subnetpool onboarding 
API does ...)
-       {DLA-4735-1}
+       {DSA-6444-1 DLA-4735-1}
        - neutron 2:28.0.1-2 (bug #1143170)
        NOTE: https://security.openstack.org/ossa/OSSA-2026-032.html
        NOTE: https://bugs.launchpad.net/neutron/+bug/2152113
@@ -59932,12 +59981,14 @@ CVE-2026-42947 (A flaw in Naxclow's platform\u2019s 
onboarding workflow allows a
 CVE-2026-42932 (Naxclow device identifiers use fixed manufacturing prefixes 
combined w ...)
        NOT-FOR-US: Naxclow
 CVE-2026-42306 (Moby is an open source container framework. In Docker Engine 
prior to  ...)
+       {DSA-6443-1}
        - docker.io 28.5.2+dfsg4-3 (bug #1139967)
        NOTE: 
https://github.com/moby/moby/security/advisories/GHSA-rg2x-37c3-w2rh
        NOTE: Fixed by: 
https://github.com/moby/moby/commit/43fa458a9c40873867e75221454de10709b04236 
(docker-v29.5.1)
 CVE-2026-41581 (Frappe is a full-stack web application framework. Prior to 
versions 15 ...)
        NOT-FOR-US: Frappe
 CVE-2026-41568 (Moby is an open source container framework. In Docker Engine 
prior to  ...)
+       {DSA-6443-1}
        - docker.io 28.5.2+dfsg4-3 (bug #1139966)
        NOTE: 
https://github.com/moby/moby/security/advisories/GHSA-vp62-88p7-qqf5
        NOTE: Fixed by: 
https://github.com/moby/moby/commit/64a22d80b93ddc1416b501b5145df02947312249 
(docker-v29.5.1)
@@ -64382,6 +64433,7 @@ CVE-2026-45290 (Cloudburst Network provides network 
components used within Cloud
 CVE-2026-42824 (Improper neutralization of special elements used in a command 
('comman ...)
        NOT-FOR-US: Microsoft
 CVE-2026-41567 (Moby is an open source container framework. In versions prior 
to 29.5. ...)
+       {DSA-6443-1}
        - docker.io 28.5.2+dfsg4-3 (bug #1139965)
        NOTE: 
https://github.com/moby/moby/security/advisories/GHSA-x86f-5xw2-fm2r
        NOTE: Fixed by: 
https://github.com/moby/moby/commit/2022313ffe5a8c04890b5295bc52670ee6df8070 
(docker-v29.5.1)
@@ -108232,6 +108284,7 @@ CVE-2026-34042 (act is a project which allows for 
local running of github action
 CVE-2026-34041 (act is a project which allows for local running of github 
actions. Pri ...)
        NOT-FOR-US: nektos act
 CVE-2026-34040 (Moby is an open source container framework. Prior to version 
29.3.1, a ...)
+       {DSA-6443-1}
        - docker.io 28.5.2+dfsg4-2 (bug #1136031)
        [bookworm] - docker.io <no-dsa> (Minor issue)
        NOTE: 
https://github.com/moby/moby/security/advisories/GHSA-x744-4wpc-v9h2
@@ -108240,6 +108293,7 @@ CVE-2026-34040 (Moby is an open source container 
framework. Prior to version 29.
 CVE-2026-34036 (Dolibarr is an enterprise resource planning (ERP) and customer 
relatio ...)
        - dolibarr <removed>
 CVE-2026-33997 (Moby is an open source container framework. Prior to version 
29.3.1, a ...)
+       {DSA-6443-1}
        - docker.io 28.5.2+dfsg4-2 (bug #1136031)
        [bookworm] - docker.io <no-dsa> (Minor issue)
        NOTE: 
https://github.com/moby/moby/security/advisories/GHSA-pxq6-2prw-chj9
@@ -109223,9 +109277,11 @@ CVE-2026-33750 (The brace-expansion library 
generates arbitrary strings containi
        NOTE: 
https://github.com/juliangruber/brace-expansion/security/advisories/GHSA-f886-m6hf-6m8v
        NOTE: Fixed by: 
https://github.com/juliangruber/brace-expansion/commit/311ac0d54994158c0a384e286a7d6cbb17ee8ed5
 (v2.0.3)
 CVE-2026-33748 (BuildKit is a toolkit for converting source code to build 
artifacts in ...)
+       {DSA-6443-1}
        - docker.io 28.5.2+dfsg4-3 (bug #1140189)
        - golang-github-moby-buildkit <itp> (bug #1094971)
 CVE-2026-33747 (BuildKit is a toolkit for converting source code to build 
artifacts in ...)
+       {DSA-6443-1}
        - docker.io 28.5.2+dfsg4-3 (bug #1140189)
        - golang-github-moby-buildkit <itp> (bug #1094971)
 CVE-2026-33745 (cpp-httplib is a C++11 single-file header-only cross platform 
HTTP/HTT ...)



View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/58a2686924535e8385e3f53fc24c8022d50e8e40

-- 
View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/58a2686924535e8385e3f53fc24c8022d50e8e40
You're receiving this email because of your account on salsa.debian.org. Manage 
all notifications: https://salsa.debian.org/-/profile/notifications | Help: 
https://salsa.debian.org/help


_______________________________________________
debian-security-tracker-commits mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits

Reply via email to